Storage News
Security News
Networking News 
FREE NEWSLETTERS
search
 

internet.commerce
Partner With Us
Free eCommerce Demo
Calling Cards
Promotional Products
Imprinted Promotions
Web Design
Baby Photo Contest
Car Donations
Laptops
Disney World Tickets
Memory
Logo Design
Best Price
Find Software
Promos and Premiums

internet.com
IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers




Turbo Screen Sharing
Adobe Acrobat Connect Professional offers users the ability to have a more productive and engaging web conferencing experience while providing the IT department with a program that efficiently utilizes bandwidth and minimally impacts the infrastructure. Learn More! »

Informal Learning: Extending the Impact of Enterprise Ideas and Information
Forward-thinking organizations are turning to enterprise learning in their quest to be better informed, better skilled, better supported at the point of need, and more competitive in their respective marketplaces. Learn More! »

Rapid E-Learning: Maturing Technology Brings Balance and Possibilities
Rapid e-learning addresses both time and cost issues by using technology tools to shift the dynamics of e-learning development. Learn why more skilled learning professionals use these tools and how you can get a solution to keep pace with your business demands. »

Delivering on the Promise of ELearning
This white paper defines the framework to launch e-learning as a set of teaching, training, and learning practices not bound by a specific technology platform or learning management system. It offers practical suggestions for creating digital learning experiences that engage learners by building interest and motivation and providing opportunities for active participation. »
Latest Headlines
Security News
Is DNSSEC the Answer to Internet Security?
Who's Really at Risk From the DNS Flaw?
DNS at Risk From Multivendor Cache Poisoning
FREE Sophos Endpoint Assessment Test Missing OS patches? Security software up to date? Scan your computer for security risks.

Security

Anti-spam | Anti-virus | Biometrics | Encryption | Filtering/Monitoring | Firewalls | Identity | Intrusion Detection/Prevention | Privacy | Security Administration Tools | Tools
Submit Products *

Coverity Prevent / Coverity Thread Analyzer

Analyze Source Code For Defects, Security Vulnerabilities

Coverity's flagship product offering is Coverity Prevent, a source code analysis platform targeted to development shops and enterprise IT development departments. Coverity Prevent analyzes source code at compile time, identifying potential code defects, security vulnerabilities, and concurrency issues in the code and providing tools that enable developers to rectify the code issues discovered. The application provides an interface within which the full path to each discovered defect is displayed, source code is displayed (cross-referenced and linked by uses and definitions), and critical attributes of the defect are inlined within the source code.

Flavors of Coverity Prevent are available for use in both C/C++ and Java environments. Platforms supported for C/C++ developers include Windows, Linux, Mac OS X, Solaris, HP-UX and more; with supported compilers including G++, GCC, MS Visual Studio, and Sun C/C++, to name just a few. The vendor states that support for other ANSI C compatible compilers is available on request. Supported Java environments include Windows, Solaris. Mac OS X, and Linux with JDK 1.4+.

In brief, Coverity Prevent's methodology is to first generate a "Software DNA" mapping of the application and then apply a series of individual analysis engines against the DNA mapping towards the goal of thoroughly understanding the application's functionality. The DNA mapping is created via a monitoring layer that operates between the build and operating systems and intercepts all complier calls (C/C++), or source code scanning (Java). Analysis engines applied to the resulting DNA map include such entries as the Path Flow Engine (graphs control flows through functions), the Statistical Engine (responsible for the analysis of the behavioral characteristics of the code base as a whole), and the False Path Engine (solving of branch conditions on the current path), to name a few. The Boolean Satisfiability (SAT) engine, in particular, seeks to translate software operations into boolean operators and values to determine whether each formula is in fact "satisfiable," i.e. whether any combination of possible true/false variables within the formula will result in the overall formula as being "true."

On top of these analysis engines the vendor offers a series of modules dedicated to the identification of defects in three main categories: "Crash Causing Defects" (memory errors, logic errors, pointer errors, etc.), "Security Vulnerabilities," and "Concurrency Defects." Additionally, "solvers" designed for use specifically with the SAT engine include the False Path Pruning Solver, which determines if the path to an identified defect is indeed feasible and therefore enables the product to reject those defects which are unfeasible (in an attempt to reduce false-positive reports). Note that not all analysis engines and modules may be available for both the C/C++ and Java flavors of the product; visit the vendor's site for further details.

Other products from the vendor include Coverity Extend, which is a complementary module to Coverity Prevent C/C++ that provides the ability to define/create custom checks to look for organization-specific code violations; and the new Coverity Thread Analyzer for Java, a standalone product for Windows (XP/Server 2003), Linux, Solaris, or Mac OS X w/JDK 1.5 that observes Java code as it is executed towards the specific goal of identifying race conditions or deadlocks. Coverity Thread Analyzer for Java can be used in combination with Coverity Prevent.

Coverity Prevent, Coverity Extend, and Coverity Thread Analayzer for Java are available now. Base pricing for Prevent is $30,000, with Extend priced at 10% of the Prevent license. Base pricing for Thread Analyzer is $20,000.

Contact Coverity for further information.

product submission by EITPlanet Staff

E-Mail this page to a colleague
send info about Coverity Prevent / Coverity Thread Analyzer

Suggest a link
for the Coverity Prevent / Coverity Thread Analyzer fact sheet

fact sheet
DPW id#: 1173456750
date posted: May 8, 2008
category: Security:Security Administration Tools
platform: Java: Windows; Solaris; Linux; Mac OS X. C/C++: Windows; Solaris; NetBSD; Mac OS X; Linux; HP-UX; FreeBSD.
vendor: Coverity, Inc
(coverity.com/)


Security

Anti-spam | Anti-virus | Biometrics | Encryption | Filtering/Monitoring | Firewalls | Identity | Intrusion Detection/Prevention | Privacy | Security Administration Tools | Tools
Submit Products *

Latest category updates via our RSS feed
RSS




Jupiter Online Media: internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and Jupiter Online Media

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Web Hosting | Newsletters | Tech Jobs | Shopping | E-mail Offers